SkarpSkarp

Chapter 3 of 10

Assessing Likelihood, Impact, and Exposure

Not all risks deserve the same attention; this module walks through practical ways to judge which threats are most likely to hurt your supply chain and by how much.

15 min readen

1. From Risk List to Risk Priorities

From List to Priorities

You already mapped where things can go wrong. The next challenge is deciding which risks deserve attention first so limited time and budget go to the most important threats.

Three Core Ideas

We focus on three ideas: likelihood (how probable a risk is), impact (how bad it is if it happens), and exposure (how much of your operations or revenue is affected).

Why This Matters in 2026

More frequent disruptions, stricter regulations, and board-level pressure mean companies must show a structured approach to risk, not just react when things break.

Your Learning Goals

You will learn to distinguish likelihood, impact, and exposure; build and read a simple risk matrix; and compare qualitative scoring with quantitative metrics like expected loss.

2. Clarifying Likelihood, Impact, and Exposure

What Is Likelihood?

Likelihood is the probability a specific risk event occurs in a given time window, often described as Rare, Possible, or Likely, or as a percentage such as 20% per year.

What Is Impact?

Impact is how severe the consequences are if the event occurs. In supply chains this includes money lost, downtime, delivery delays, and compliance or reputation damage.

What Is Exposure?

Exposure is how much of your organization is affected: share of revenue tied to a supplier, number of sites relying on a hub, or percent of volume through one port.

How They Work Together

Likelihood and impact form the classic risk matrix. Exposure refines impact by showing how concentrated or systemic the damage would be across your network.

3. Concrete Supply Chain Scenarios

Scenario A: Port Congestion

60% of your imported components pass through one Asian port. Likelihood is high, impact is weeks of delay and extra cost, and exposure is very high because most inbound volume depends on it.

Scenario B: Cyberattack on WMS

Your main DC uses a single cloud WMS. Likelihood is moderate, impact is 2–3 days of disruption and penalties, and exposure is high for that DC but not for other regions.

Scenario C: Supplier Strike

A smaller supplier of non-critical packaging may face a strike. Likelihood is moderate, impact is small with alternatives available, and exposure is low to a small product line.

Comparing the Three

Port congestion is high likelihood, high impact, high exposure; cyberattack is moderate likelihood, high impact; supplier strike is moderate likelihood, low impact. Port congestion clearly ranks higher.

4. Building a Simple Risk Matrix (Heat Map)

What Is a Risk Matrix?

A risk matrix or heat map combines likelihood and impact on a grid so you can see which risks are both probable and severe at a glance.

Step 1: Choose Scales

Use 1–5 scales for likelihood and impact. For example, likelihood from 1 Rare to 5 Almost Certain, and impact from 1 Insignificant to 5 Severe.

Step 2: Define Criteria

Reduce subjectivity by linking scores to thresholds, such as dollar loss ranges or hours of downtime for each impact level from 1 to 5.

Step 3: Plot and Interpret

Plot risks with likelihood on the X-axis and impact on the Y-axis. Top-right cells (high–high) are priority. Size or labels can show exposure, such as percent of revenue affected.

5. Place Risks on a Matrix (Thought Exercise)

Use the three scenarios from Step 3 and mentally place them on a 1–5 likelihood and 1–5 impact matrix.

Assume:

  • Likelihood scale: 1 Rare, 2 Unlikely, 3 Possible, 4 Likely, 5 Almost Certain
  • Impact scale (financial + operational combined): 1 Insignificant, 2 Minor, 3 Moderate, 4 Major, 5 Severe

Task:

  1. For each scenario, assign a likelihood score (1–5) and an impact score (1–5).
  2. Then rank the three risks from highest to lowest priority.

Scenarios (reminder):

  • A: Port congestion at major Asian hub
  • B: Cyberattack on main WMS
  • C: Strike at secondary supplier

Write down your answers before viewing the suggested solution below.

Suggested answers (one reasonable approach):

  • A: Likelihood 4 (Likely), Impact 4 (Major)
  • B: Likelihood 3 (Possible), Impact 4 (Major)
  • C: Likelihood 3 (Possible), Impact 2 (Minor)

Ranking:

  1. A (4,4) – high likelihood and major impact
  2. B (3,4) – slightly less likely but still major impact
  3. C (3,2) – similar likelihood but much lower impact

Reflection questions:

  • Would your scores change if the port handled only 20% of your volume instead of 60%? How does that relate to exposure?
  • How might regulation or customer expectations change your impact scores (for example, for a cyberattack)?

6. Qualitative vs Quantitative Assessment

Qualitative Assessment

Qualitative assessment uses categories like High/Medium/Low or 1–5 scores without exact numbers. It is easy to start and works with limited data, but it is subjective.

Quantitative Assessment

Quantitative assessment uses numbers: probabilities, hours of downtime, or dollar losses. It enables cost–benefit analysis but needs data and can give a false sense of precision.

Semi-Quantitative in Practice

Many firms use semi-quantitative scales, where scores map to ranges, such as impact 4 meaning $500k–$2m loss. This balances practicality with analytical rigor.

What You Will Use

In this module you will combine qualitative 1–5 scoring with simple quantitative metrics like expected loss or expected downtime for selected critical supply chain risks.

7. Calculating Expected Loss and Downtime

A basic quantitative idea you should know is expected value.

  • Expected loss = probability of the event × loss if it occurs.
  • Expected downtime = probability of the event × downtime if it occurs.

This does not capture everything (for example, tail risks, cascading failures), but it is a useful starting point.

Example assumptions:

  • Port congestion (Scenario A):
  • Probability per year = 0.4 (40%)
  • Loss if it occurs = $1,000,000
  • Cyberattack (Scenario B):
  • Probability per year = 0.2 (20%)
  • Loss if it occurs = $1,500,000

Below is a short Python example to compute expected loss and expected downtime for a few risks. You do not need to run it, but reading it will help you see how the logic works.

8. Quick Check: Expected Loss

Use the idea of expected loss to answer this question.

A supplier disruption has:

  • 10% chance per year (0.10)
  • $2,000,000 loss if it occurs

What is the expected loss per year?

A supplier disruption has a 10% chance per year and would cost $2,000,000 if it occurs. What is the expected loss per year?

  1. $20,000
  2. $200,000
  3. $2,000,000
  4. $10,000,000
Show Answer

Answer: B) $200,000

Expected loss = probability × loss = 0.10 × $2,000,000 = $200,000 per year. This is the average loss if you could repeat many years under the same conditions.

9. Integrating Exposure into Your Prioritization

Exposure helps you distinguish between two risks that have similar likelihood and impact per event but affect very different parts of your business.

Activity:

  1. Consider two risks:
  • Risk X: Factory fire at Plant A, which makes 80% of your main product line.
  • Risk Y: Factory fire at Plant B, which makes 5% of a niche product line.
  1. Assume:
  • Probability of fire at each plant: 1% per year.
  • Financial loss if each plant burns down: $10,000,000.
  1. On a simple likelihood–impact matrix, X and Y look identical:
  • Same probability
  • Same loss per event
  1. Now think about exposure:
  • Plant A disruption affects 80% of your main revenue stream.
  • Plant B disruption affects only 5% of a niche line.

Questions to reflect on:

  • Which risk would you prioritize for mitigation and why?
  • How could you represent this difference on your heat map without changing the likelihood or impact scores?

Possible answers:

  • Most companies would prioritize Risk X because the exposure of key products and customers is much higher.
  • On a heat map, you might:
  • Use a larger symbol for Risk X
  • Add text like "affects 80% of main product revenue" under Risk X
  • Tag it as "systemic" vs. "localized" risk.

This illustrates why modern supply chain risk management (as practiced in 2026) increasingly treats exposure and concentration risk as central, not optional.

10. Key Term Review

Flip the cards to review core concepts from this module.

Risk likelihood
The probability that a specific risk event occurs in a given time window (for example, per year), often expressed as categories like Rare to Almost Certain or as a percentage.
Risk impact
The severity of consequences if a risk event occurs, typically measured in financial loss, operational downtime, customer service impact, and compliance or reputational damage.
Risk exposure
The extent of the organization affected by a risk, such as the share of revenue, number of sites, or percentage of volume dependent on a vulnerable supplier, facility, or route.
Risk matrix (heat map)
A visual tool that plots risks on a grid of likelihood versus impact, often color-coded, to highlight which risks are low, medium, or high priority.
Qualitative risk assessment
An approach that uses descriptive categories or scores (for example, 1–5, High/Medium/Low) without precise numerical probabilities or loss amounts.
Quantitative risk assessment
An approach that estimates numerical probabilities, losses, and downtime, enabling calculations such as expected loss and cost–benefit analysis of mitigation options.
Expected loss
A basic quantitative metric calculated as probability of an event multiplied by the loss if it occurs, representing the long-run average loss per time period.

Key Terms

Risk impact
The magnitude of negative consequences if a risk event occurs, typically including financial, operational, customer, and compliance or reputational effects.
Expected loss
The product of the probability of a risk event and the loss if it occurs, representing the average loss per period over many repetitions under similar conditions.
Risk exposure
The portion of an organization’s operations, revenue, assets, or partners that would be affected by a given risk, reflecting concentration and systemic vulnerability.
Risk likelihood
The probability that a specific risk event occurs within a defined time period, such as a year, sometimes expressed as a qualitative level (for example, Likely) or a numerical probability.
Concentration risk
The risk that a large share of business depends on a small number of suppliers, sites, or routes, increasing vulnerability to localized disruptions.
Risk matrix (heat map)
A two-dimensional grid that maps risks according to their likelihood and impact, often with color coding to show relative priority levels.
Qualitative risk assessment
A method that evaluates risks using descriptive categories or ordinal scales instead of precise numerical estimates.
Quantitative risk assessment
A method that evaluates risks using numerical estimates of probability, loss, and other metrics, supporting calculations like expected loss.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself